mirror of
https://github.com/mudler/LocalAI.git
synced 2026-07-30 18:09:05 -04:00
build-test.yaml, yaml-check.yml and secscan.yaml had no concurrency block at all, so every push to a PR stacked another full batch instead of superseding the previous one. build-test carries a macos-latest job, the scarcest runner class we use, and secscan fires on every push to every branch because its `push:` trigger is unfiltered. build-test and yaml-check use the same group idiom as lint.yml and the other eleven workflows that already have one: key on the PR number so pushes to a PR share a group, and cancel only on pull_request. On a master push the key falls back to github.sha and cancel-in-progress is false, so master runs never cancel each other -- that is deliberate, since backend.yml builds only the backends a given commit touched and superseding would drop those builds. secscan needs a different key: it has no pull_request trigger, so the shared idiom would fall back to the unique-per-commit sha and dedup nothing. It groups on github.ref instead, and excludes master from cancellation for the same per-commit reason. Cancelling a superseded feature-branch scan is safe because the only output is a SARIF upload and code scanning keeps the latest result per ref. No behaviour change on master for any of the three. Assisted-by: Claude:claude-opus-4-8 [Claude Code] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> Co-authored-by: Ettore Di Giacinto <mudler@localai.io>